检测到您已登录华为云国际站账号,为了您更好的体验,建议您访问国际站服务网站 https://www.huaweicloud.com/intl/zh-cn
不再显示此消息
swr:SubnetId string Single-valued Controls permissions based on subnet IDs. swr:EnablePublicNameSpace boolean Single-valued Controls whether public organizations can be created in SWR Enterprise Edition. swr:EnableObsEncrypt boolean Single-valued Controls whether buckets must be encrypted
gaussdb:instance:bindEIP Grants permission to bind an EIP. write instance - gaussdb:instance:check Grants permission to check instance information. read instance - gaussdb:instance:createInstance Grants permission to create a DB instance. write instance gaussdb:BackupEnabled gaussdb:Encrypted
ecs:cloudServers:showServer Grants permission to query ECS details. read instance * - ecs:cloudServers:attach Grants permission to attach disks to an ECS. write instance * evs:Encrypted ecs:KmsKeyId ecs:VolumeId evs:Encrypted ecs:cloudServers:listServerBlockDevices Grants permission
EVS disks attached to a BMS. read instance* g:EnterpriseProjectId g:ResourceTag/<tag-key> bms:servers:create Grants permission to create BMSs. write - g:EnterpriseProjectId g:TagKeys g:RequestTag/<tag-key> eip:AssociatePublicIp bms:Flavorld bms:VpcId bms:SubnetId bms:KmsKeyId evs:Encrypted
Table 4 Service-specific condition keys supported by IMS Service-specific Condition Key Type Single-valued/Multivalued Description ims:TargetOrgPaths string Multivalued Filters access based on the Organizations Path of the specified sharing account. ims:Encrypted boolean Single valued
Table 1 Actions supported by EVS Action Description Access Level Resource Type (*: required) Condition Key evs:volumes:create Grants permission to create disks. write volume * - - g:RequestTag/<tag-key> g:TagKeys g:EnterpriseProjectId evs:Encrypted cbr:VaultId evs:volumes:list Grants
EnterpriseProjectId g:ResourceTag/<tag-key> rds:instance:deleteNode Grants permission to delete a database node. write - - rds:instance:createDns Grants permission to create a private DNS server. write - - rds:instance:create Grants permission to create a DB instance. write - rds:Encrypted
g:EnterpriseProjectId cce:node:add Grants permission to manage a node. write cluster * cce:ClusterId evs:Encrypted g:EnterpriseProjectId cce:node:remove Grants permission to release a node. write cluster * cce:ClusterId g:EnterpriseProjectId cce:node:migrate Grants permission to
Table 4 Service-specific condition keys supported by DDS Service-specific Condition Key Type Description dds:Encrypted boolean Filters access by the tag key specifying whether to enable disk encryption transferred in the request parameter. dds:BackupEnabled boolean Filters access
Specifically, requests are encrypted using the access key ID (AK) and secret access key (SK) to provide higher security. AK/SK-based Authentication AK/SK-based authentication supports API requests with a body not larger than 12 MB.